Privacy Notice
Last updated: September 20, 2026
M1 Factory, Inc. operates Homie and KnoMe. This notice explains how we handle personal information across our websites, apps, supported connections, messaging, voice, and support. Contact meet@m1factory.com with a privacy request.
The short version
We process information you provide and information obtained through connections you authorize to deliver the features you use. Some features send information to AI or other processing providers. An account connection, permission to share with an AI application, and permission to take an action are separate decisions.
We do not sell personal information or share it for cross-context behavioral advertising. We do not use private customer content to train or fine-tune general-purpose AI models. Processing a request can still involve provider storage and security logs; no training does not mean no retention.
1. Information we collect and why
- Account information: phone number, account ID, optional name, verification events, and membership details, for sign-in, security, account management, and support.
- Conversations and tasks: messages, replies, instructions, links, photos, documents, task details, and results, to provide assistance, maintain context, and carry out supported requests.
- Connected accounts: account identifiers, permissions, connection credentials handled by our authorization infrastructure, and information requested from an authorized source, such as Gmail messages or Calendar events, to operate the connection and requested features.
- Saved and shared information: records, files, extracted fields, preferences, household information, and sharing settings, to store and retrieve information and make authorized disclosures.
- Voice and messaging: audio, transcripts or summaries, phone numbers, channel identifiers, consent, and delivery records, to provide the communication features you use.
- Security and usage information: IP address, device and browser information, internal account and session identifiers, feature events, errors, permissions, approvals, and action records, to operate and protect the service, diagnose problems, and understand usage.
- Support and billing: information you send to support and, if you purchase a paid feature, transaction and billing information needed to administer it. Any payment provider is identified when payment is requested.
Information may come from you, an authorized account, another household member, a person inviting you, or a service used to complete a request. Personal information includes messages, relationships, and inferences about people, as well as direct identifiers. Connected accounts may contain sensitive information about you or others.
2. Connected accounts and AI
Account access and privacy checks
The current Gmail connection requests full Gmail access (https://mail.google.com/) and your email address for account identification. This Google permission is broader than the app’s read-only Gmail tools: the current allowlist permits message, attachment, and profile reads, not sending or deleting email. Permissions in KnoMe further restrict which results an AI application may receive. No contacts permission is requested by this configuration.
For supported Google connections, Composio helps manage authorization and execute account requests. Google sends requested information through this infrastructure to our backend. Composio and our backend can process the original information before a permitted result is returned to an AI application.
Privacy checks help identify and withhold supported sensitive content. They do not guarantee that every sensitive detail will be detected. Turning off an AI application’s access does not necessarily disconnect the source account or delete information already stored.
Homie assistance and optional analysis
Homie uses OpenAI to generate responses from your message, relevant permitted context, and tool results. Enabled audio or document features may send selected audio, files, or text for transcription or analysis. A document can be sent to a processing provider before its extracted information is saved privately.
Web research may disclose search terms derived from your request to a search service. An AI-authorship check may send the selected text to Pangram. These checks provide uncertain signals, not proof that content is trustworthy or deceptive.
AI applications you choose
A connected AI application receives results allowed by its KnoMe permissions. Its provider handles those results under your agreement and settings with it. This includes any retention or training choices that apply to your external AI account. Revoking KnoMe access does not delete an external conversation or control information you gave that application through another route.
3. Who processes your information
The providers used depend on the product and features you use. Some operate on our behalf; connected account providers, messaging platforms, and AI applications you independently choose also have their own responsibilities and privacy terms.
| Provider | Purpose and information involved |
|---|---|
| Supabase | Account authentication, database, and file storage; account information and stored service content. |
| Railway | Application and worker hosting; content processed by the hosted services and operational logs. |
| Cloudflare | Web delivery and protection for supported sites; network, request, and security information. |
| Composio | Connected-account authorization and requests; connection credentials, request details, and returned account content. Connector diagnostics may include request and response content. |
| Source of authorized Gmail and Calendar information; receives account requests and supported changes. | |
| OpenAI | Homie responses, supported search, audio, and document analysis; submitted content and relevant permitted context. Where conversation classification is enabled, portions of an interaction are also processed as explained below. |
| PostHog | Product analytics and masked session replay; usage events, page layouts, clicks, scrolling, and internal account and session identifiers. |
| Twilio and Meta/WhatsApp | Authentication or supported communications; phone numbers, message or call content, and delivery information, depending on the channel. Enabled speech features may use speech providers such as Deepgram, ElevenLabs, or Google through the communications service. |
| Pangram | AI-authorship analysis of selected text when that check is used. |
| An AI application or recipient you choose | Information you authorize us to return or send, handled under that recipient’s own terms and settings. |
Providers may retain information for service delivery, security, legal compliance, and other purposes allowed by their applicable agreements. We do not promise zero retention across these services. For example, Composio documents tool-log retention of up to one year under its standard settings; shorter or content-free logging depends on configuration. Composio retention information
Our current Composio project is configured not to store new tool-call request and response payloads in its logs. Audit metadata is still retained, and this setting does not delete payloads stored before it was enabled or eliminate temporary processing of attachments.
We may also disclose information to comply with law, respond to valid legal requests, protect people and the service, or complete a business transaction subject to applicable safeguards. We do not sell or share phone numbers or messaging opt-in information for third-party marketing.
4. Google data and model training
Homie and KnoMe’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements, and the applicable Google Workspace user-data policy.
We use Google data for the supported features you authorize. We do not use it for advertising, data brokerage, creditworthiness decisions, or training or improving general-purpose AI models. A general account connection does not authorize unrelated research or marketing.
We do not train or fine-tune general-purpose AI models on private customer content. The business AI services we use have their own retention and security arrangements. Your independently chosen AI application may operate under different terms.
5. Household sharing and human access
Information deliberately placed in a shared conversation or record is available to its authorized audience. Private information remains subject to the relevant account and sharing permissions. Household membership or payment alone does not authorize access to another adult’s connected account.
Authorized personnel may access relevant information to provide support, investigate security or abuse, meet legal obligations, or perform review you separately authorize. Human access to Google-derived data is limited to circumstances permitted by Google’s policies, including specific consent where required.
If you choose to share an exchange or participate in an optional review program, the review flow describes what you are sharing and the access period. A support request or one shared exchange does not grant access to your entire account or inbox.
6. Cookies, analytics, and review
Cookies and browser storage support authentication, security, and preferences. We use PostHog for operational and product analytics. During early access, browser analytics and masked session replay are enabled by default where available. We use recordings of page layouts and interactions to investigate problems and improve KnoMe. Private text and inputs are masked; a fixed set of product labels and connection statuses remains readable; images, embedded content, console logs, network bodies, and headers are excluded. Internal account identifiers can be linked to an account; they are not anonymous data.
You can turn browser analytics and replay off using “Help improve KnoMe” in your profile. Existing browser opt-outs are respected. This preference is specific to your browser. Server-side operational and security events are separate from browser replay. Contact us about analytics choices; blocking essential storage may prevent sign-in.
Conversation classification is disabled for the current web pilot. If enabled in a separately disclosed flow, Homie sends portions of your message and its reply to OpenAI to generate fixed categories such as intent and outcome. Those categories, rather than the message text, are sent to PostHog. This is separate from generating the response itself.
Where applicable law requires consent for optional processing or storage technologies, that consent is required separately from acceptance of our terms. An account connection is not consent to unrelated analytics.
7. Retention and deletion
We keep information for as long as needed for the purposes described here, considering the feature, your choices, security needs, and legal requirements:
- Account information and saved content support your account until you delete the content, close the account, or it is no longer needed.
- Conversations, tasks, transcripts, and summaries support continuity and records of requested work. Their retention depends on the feature and any retention choice it provides.
- Permissions, consent, action evidence, and security records may need to be retained after an account or connection closes to document authorization, investigate misuse, or meet legal obligations.
- Temporary processing files, diagnostics, analytics, and provider logs follow their relevant cleanup or retention settings. Their lifetime can differ from the content displayed in your account.
- Backups can retain copies until they expire or are overwritten. Records needed for legal obligations or disputes may be retained for those purposes.
Contact us to request deletion or information about retention for a particular feature. We assess the request, clarify whether it covers Homie, KnoMe, or both, and arrange applicable deletion, including with providers processing on our behalf. We explain applicable exceptions or limitations and respond within the period required by law.
Disconnecting an account stops that connection; revoking an AI permission stops future access under it. Neither automatically deletes saved information. Deleting our copy cannot recall information already received by another person or an independently chosen AI provider. Their own deletion controls may also be needed.
8. Security
We use authentication, access controls, encryption, and operational safeguards designed to protect information. Some server operations have privileged access and rely on application authorization and operational controls.
The service is not end-to-end encrypted against M1 Factory and all processing providers: our servers and necessary providers can process content to operate supported features. No system or sensitive-data detector is perfect.
We investigate security incidents and notify affected people and authorities when required by applicable law. Read Trust & Security for more about our approach.
9. Your choices and rights
Use available controls to manage connections, AI permissions, shared information, and messaging. For supported SMS messaging, reply STOP to opt out or HELP for assistance.
Depending on your location and applicable law, you may have rights to access, correct, delete, or export information; withdraw consent; object to or restrict processing; limit certain sensitive-data uses; opt out of sale, targeted advertising, or certain profiling; and appeal a request decision. We do not sell personal information or use it for cross-context behavioral advertising.
Send requests, including requests from authorized agents, to meet@m1factory.com. We verify identity proportionately, explain any permitted refusal or extension, and respond within the applicable legal period. For an appeal, identify your message as a privacy appeal. We do not discriminate against you for exercising protected rights. You may complain to the relevant privacy regulator.
Do not email passwords, sign-in codes, or full identity documents. If additional verification is necessary, we will explain an appropriate method.
10. Children and sensitive uses
The service is for adult account holders and is not directed to children. Adults may provide limited information about dependents through supported household features, so we may process information about children without offering child-operated accounts. Contact us if you believe a child is using an account or has provided information in an unsupported way.
Health, identity, and financial information may appear in connected accounts. Submit sensitive records deliberately only to a feature that expressly supports them and explains its processing. Our consumer service does not provide a HIPAA Business Associate Agreement. Other privacy laws can still apply to health information.
11. International processing
We and our providers may process information in the United States and other countries where their services operate. Protections may differ from those in your location. When applicable law requires a transfer safeguard, it must be in place for that processing. Contact us for information about the arrangements applicable to your data.
Where EEA or UK law applies, our legal bases are performance of the service contract for necessary account and feature processing; legitimate interests in service security, reliability, and appropriate improvement; legal obligations; and consent where required for optional processing. Special-category information requires an additional lawful condition. You may object to processing based on legitimate interests or withdraw consent without affecting earlier lawful processing.
12. Changes and contact
We update the date above when this notice changes. We provide notice of material changes as required and obtain new consent when required before using information for a new purpose.
M1 Factory, Inc. — meet@m1factory.com.
Read our Terms of Service and Trust & Security page.